Exploitation Summary
EIP tracks 7 public exploits for CVE-2006-6927. PoCs published by laurent gaffie.
AI-analyzed exploit summary The provided text describes SQL injection vulnerabilities in Grandora Rialto version 1.6, with example URLs demonstrating unsanitized input parameters. No actual exploit code is present, only a vulnerability description and proof-of-concept URLs.
Description
Multiple SQL injection vulnerabilities in Rialto 1.6 allow remote attackers to execute arbitrary SQL commands via (1) the uname (username) and (2) pword (passwd) fields in (a) admin/default.asp; the (3) ID parameter to (b) listfull.asp or (c) printmain.asp; the (4) cat parameter to (d) listmain.asp, (e) searchoption.asp, or (f) searchmain.asp; the (5) Keyword parameter to (g) searchkey.asp; the (6) area parameter to searchmain.asp or searchoption.asp; the (7) searchin parameter to searchkey.asp; or the (8) cost1, (9) cost2, (10) acreage1, or (11) squarefeet1 parameters to searchoption.asp. NOTE: some of these details are obtained from third party information.
Exploits (7)
The provided text describes SQL injection vulnerabilities in Grandora Rialto version 1.6, with example URLs demonstrating unsanitized input parameters. No actual exploit code is present, only a vulnerability description and proof-of-concept URLs.
The provided text describes SQL injection and XSS vulnerabilities in Grandora Rialto version 1.6, with example URLs demonstrating potential exploitation vectors. It lacks executable exploit code but outlines the attack surface.
The provided text describes SQL injection and XSS vulnerabilities in Grandora Rialto 1.6, with example URLs demonstrating potential exploitation vectors. No actual exploit code is present.
The provided text describes SQL injection and XSS vulnerabilities in Grandora Rialto 1.6 due to insufficient input sanitization. It includes a basic example URL for SQLi exploitation but lacks executable code.
The provided text describes SQL injection and XSS vulnerabilities in Grandora Rialto 1.6 due to insufficient input sanitization. It includes a basic example URL for SQL injection but lacks executable exploit code.
The provided text describes SQL injection and XSS vulnerabilities in Grandora Rialto 1.6 due to insufficient input sanitization. It includes a basic example URL for SQL injection but lacks executable exploit code.
This exploit demonstrates SQL injection and XSS vulnerabilities in Grandora Rialto 1.6 by providing a simple payload to bypass authentication via SQLi. The PoC includes a username and password field injection to achieve authentication bypass.